Lucene search

K
nvd[email protected]NVD:CVE-2009-1686
HistoryJun 10, 2009 - 2:30 p.m.

CVE-2009-1686

2009-06-1014:30:00
CWE-20
web.nvd.nist.gov
5

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

8.1

Confidence

High

EPSS

0.022

Percentile

89.4%

WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 does not properly handle constant (aka const) declarations in a type-conversion operation during JavaScript exception handling, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted HTML document.

Affected configurations

Nvd
Node
applesafariRange4.0_beta-mac
OR
applesafariMatch0.8-mac
OR
applesafariMatch0.9-mac
OR
applesafariMatch1.0-mac
OR
applesafariMatch1.0.3-mac
OR
applesafariMatch1.1-mac
OR
applesafariMatch1.2-mac
OR
applesafariMatch1.3-mac
OR
applesafariMatch1.3.1-mac
OR
applesafariMatch1.3.2-mac
OR
applesafariMatch2.0-mac
OR
applesafariMatch2.0.2-mac
OR
applesafariMatch2.0.4-mac
OR
applesafariMatch3.0-mac
OR
applesafariMatch3.0.2-mac
OR
applesafariMatch3.0.3-mac
OR
applesafariMatch3.0.4-mac
OR
applesafariMatch3.1-mac
OR
applesafariMatch3.1.1-mac
OR
applesafariMatch3.1.2-mac
OR
applesafariMatch3.2.3-mac
Node
applesafariRange3.2.3-windows
OR
applesafariMatch3.0-windows
OR
applesafariMatch3.0.1-windows
OR
applesafariMatch3.0.2-windows
OR
applesafariMatch3.0.3-windows
OR
applesafariMatch3.0.4-windows
OR
applesafariMatch3.1-windows
OR
applesafariMatch3.1.1-windows
OR
applesafariMatch3.1.2-windows
OR
applesafariMatch3.2-windows
OR
applesafariMatch3.2.1-mac
OR
applesafariMatch3.2.1-windows
OR
applesafariMatch3.2.2-windows
VendorProductVersionCPE
applesafari*cpe:2.3:a:apple:safari:*:-:mac:*:*:*:*:*
applesafari0.8cpe:2.3:a:apple:safari:0.8:-:mac:*:*:*:*:*
applesafari0.9cpe:2.3:a:apple:safari:0.9:-:mac:*:*:*:*:*
applesafari1.0cpe:2.3:a:apple:safari:1.0:-:mac:*:*:*:*:*
applesafari1.0.3cpe:2.3:a:apple:safari:1.0.3:-:mac:*:*:*:*:*
applesafari1.1cpe:2.3:a:apple:safari:1.1:-:mac:*:*:*:*:*
applesafari1.2cpe:2.3:a:apple:safari:1.2:-:mac:*:*:*:*:*
applesafari1.3cpe:2.3:a:apple:safari:1.3:-:mac:*:*:*:*:*
applesafari1.3.1cpe:2.3:a:apple:safari:1.3.1:-:mac:*:*:*:*:*
applesafari1.3.2cpe:2.3:a:apple:safari:1.3.2:-:mac:*:*:*:*:*
Rows per page:
1-10 of 341

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

8.1

Confidence

High

EPSS

0.022

Percentile

89.4%